Distributed Ledger Digital Credential Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in securely registering and verifying trusted authentication devices with database systems for digital credential management, leading to issues with secure access and identity verification.

Innovation Solution

A system utilizing a digital credential aware identity and access management service (DCIAMS) that employs a distributed ledger to securely store and verify digital credentials, allowing users to prove identity through a combination of cryptography and a distributed ledger, enabling secure access and reducing data theft and misrepresentation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a user possesses an authentication device for storing and providing digital credentials, then the user can securely prove qualifications and access services, but the system faces challenges in securely registering and verifying the trusted authentication device with the database system

Engineering Contradiction:
Improvesecurity of credential verificationVSAvoidcomplexity of device registration and verification
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a distributed ledger as an intermediary between the authentication device and the database system. The ledger stores verification data and enables trustless verification of authentication devices without requiring direct secure registration with the central database system. This mediator resolves the contradiction by maintaining security while simplifying the verification process.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the authentication process into separate components: the authentication device stores credentials locally, the distributed ledger stores verification data, and the database system stores user information. This segmentation allows each component to operate independently with clearly defined trust boundaries, reducing the complexity of secure registration while maintaining overall system security.

Inventive Principle:
Principle #1Segmentation

2Reliability

If digital credentials are stored and verified using traditional centralized authentication systems, then identity verification can be performed, but the systems are vulnerable to data theft and misrepresentation

Engineering Contradiction:
Improvetrustworthiness of identity verificationVSAvoiddata theft and misrepresentation
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The distributed ledger acts as a trusted intermediary that stores verification data in a decentralized and immutable manner. This eliminates the single point of failure in centralized systems, preventing data theft while maintaining verification trustworthiness. The ledger's cryptographic nature ensures data integrity and prevents misrepresentation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical authentication systems (centralized databases with passwords and tokens) with a cryptographic system based on public-key infrastructure and distributed ledger technology. This substitution fundamentally changes the security model from vulnerable centralized storage to resilient decentralized verification, eliminating data theft risks while maintaining trustworthiness.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If a distributed ledger is used to store and verify digital credentials, then secure access and identity verification are enhanced, but the system complexity and computational requirements increase

Engineering Contradiction:
Improvesecurity of digital credential verificationVSAvoidcomplexity of distributed ledger implementation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the verification data storage function from the central database system and places it in the distributed ledger. This separation allows the database system to remain simple while the ledger handles the complex verification operations. Users only need to store their credentials locally without managing complex verification infrastructure, reducing device complexity while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11641278B2Digital credential authentication
Publication Date: 2023.05.02 WORKDAY INC
  • US11641278B2 patent drawing
  • US11641278B2 patent drawing
  • US11641278B2 patent drawing

AI summary

A system for creating an identity mapping on a distributed ledger includes an interface and a processor. The interface is configured to receive a request to create an identity mapping on a distributed ledger. The processor is configured to generate an identity key pair; generate a mobile encryption key; encrypt a private identity key of the identity key pair using the mobile encryption key to create an encrypted private key; store the encrypted private key; create a mapping document; sign the mapping document with the private identity key of the identity key pair; and provide the signed mapping document to be stored in a distributed ledger.